版本如下:
version 7.1.070, Release 7577P02
交换机配置了acl 2100
写了几条rule,允许几个地址可以 permit
后面rule 写了一条deny any
使用ssh server acl 2100引用,然后SSH不能连接,客户端使用acl规则里的permit的IP地址访问
disp acl 2100没有匹配
查看日志sshs/5/,发现被另一个acl 2300匹配,但是acl2300并没有引用,disp cu | in 2300也只过滤到一条。
acl number 2100
description Deny SSh
rule 1 permit source 10.46.225.35 0
rule 5 permit source 10.46.225.75 0
rule 10 permit source 10.46.225.190 0
rule 15 permit source 10.184.45.10 0
rule 20 permit source 10.184.45.11 0
rule 200 deny
ACL 2300
Basic IPv4 ACL 2300 named YuanChengDengLuXianZhi, 12 rules,
ACL's step is 5, start ID is 0
rule 30 permit vpn-instance cddz_tfxq_mg source 10.184.45.120 0
rule 40 permit vpn-instance cddz_tfxq_mg source 10.46.20.240 0
rule 45 permit vpn-instance cddz_tfxq_mg source 10.46.225.240 0
rule 50 permit vpn-instance cddz_tfxq_mg source 10.46.225.196 0
rule 55 permit vpn-instance cddz_tfxq_mg source 10.46.225.150 0
rule 70 permit vpn-instance cddz_tfxq_mg source 10.46.20.18 0
rule 75 permit vpn-instance cddz_tfxq_mg source 10.46.225.126 0
SSH 日志
ZWZX-S10506]disp logbuffer | in SSHS/5
%Jul 18 10:01:16:965 2025 ZWZX-S10506 SSHS/5/SSHS_ACL_DENY: The SSH Connection 10.46.225.35(cddz_tfxq_mg) request was denied according to ACL rules.
%Jul 18 10:01:19:949 2025 ZWZX-S10506 SSHS/5/SSHS_ACL_DENY: The SSH Connection 10.46.225.35(cddz_tfxq_mg) request was denied according to ACL rules.
%Jul 18 10:12:59:406 2025 ZWZX-S10506 SHELL/6/SHELL_CMD: -Line=vty1-IPAddr=10.46.225.35-User=Jiangw9980; Command is disp logbuffer | in SSHS/5
%Jul 18 10:14:05:593 2025 ZWZX-S10506 SSHS/5/SSHS_ACL_DENY: The SSH Connection 10.46.225.35(cddz_tfxq_mg) request was denied according to ACL rules.
%Jul 18 10:14:06:389 2025 ZWZX-S10506 SSHS/5/SSHS_ACL_DENY: The SSH Connection 10.46.225.35(cddz_tfxq_mg) request was denied according to ACL rules.
%Jul 18 10:14:10:002 2025 ZWZX-S10506 SSHS/5/SSHS_ACL_DENY: The SSH Connection 10.46.225.35(cddz_tfxq_mg) request was denied according to ACL rules.
%Jul 18 10:16:13:903 2025 ZWZX-S10506 SSHS/5/SSHS_ACL_DENY: The SSH Connection 10.46.225.35(cddz_tfxq_mg) request was denied according to ACL rules.
%Jul 18 10:16:14:927 2025 ZWZX-S10506 SSHS/5/SSHS_ACL_DENY: The SSH Connection 10.46.225.35(cddz_tfxq_mg) request was denied according to ACL rules.
%Jul 18 10:16:18:265 2025 ZWZX-S10506 SSHS/5/SSHS_ACL_DENY: The SSH Connection 10.46.225.35(cddz_tfxq_mg) request was denied according to ACL rules.
%Jul 18 10:16:31:025 2025 ZWZX-S10506 SHELL/6/SHELL_CMD: -Line=vty1-IPAddr=10.46.225.35-User=Jiangw9980; Command is disp logbuffer | in SSHS/5
%Jul 18 10:23:57:816 2025 ZWZX-S10506 SSHS/5/SSHS_ACL_DENY: The SSH Connection 10.46.225.35(cddz_tfxq_mg) request was denied according to ACL rules.
[ZWZX-S10506]un ssh sev acl
(0)
最佳答案
不会啊,检查下rule下的配置吧
(0)
规则检查过了,那条日志里面描述的acl 2300没有被引用,ssh server acl 2100引用的是2100
规则检查过了,那条日志里面描述的acl 2300没有被引用,ssh server acl 2100引用的是2100
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明